generated: '2026-09-09' method: searched probe: true url: https://www.aedifion.com/sicherheit note: >- aedifion runs no dedicated trust-center subdomain - trust.aedifion.com and security.aedifion.com do not resolve, and the automated probe recorded no hit. It does publish a substantive security and compliance page on its main site, with a named certifying body and the certificate itself available for download, plus a security architecture section in the developer documentation. Recorded here because the compliance posture is genuinely published, not because a trust portal exists. certifications: - name: DIN EN ISO/IEC 27001 status: certified since: '2023-12' certifier: INFAZ Institut fuer Auditierung und Zertifizierung scope: 'processes and systems in all business areas' certificate_url: https://cdn.prod.website-files.com/6942a43e5bcce46ebe9f73a1/696e525b02ad6e609db2751c_2025_aedifion_certificate_iso-iec-27001_de.pdf certificate_verified: true certificate_http_status: 200 certificate_content_type: application/pdf certificate_bytes: 302351 - name: GDPR / DSGVO status: compliant evidence: Privacy policy published; all processing in Germany. hosting: provider: Hetzner Online GmbH locations: [Nuremberg, Falkenstein] country: Germany provider_certification: DIN ISO/IEC 27001 dedicated_option: 'On demand, aedifion stores and processes your data on dedicated servers.' security_posture: transport_encryption: TLS between edge device and platform; SSH as an alternative certificates: X.509 from Let's Encrypt, renewed quarterly access_control: >- Role-based access control with read or write granularity on individual datapoints; federation with LDAP and Active Directory via OpenID Connect, OAuth and SAML penetration_testing: >- Edge devices "must pass an extensive series of functional and penetration tests" before commissioning. No platform-level pentest report or summary is published. uptime_commitment: '97%' contact: general: contact@aedifion.com phone: '+49 221 98650-770' page: https://www.aedifion.com/kontakt evidence: - source: https://www.aedifion.com/sicherheit status: 200 keywords: [ISO 27001, DIN EN ISO/IEC 27001, INFAZ, DSGVO, Informationssicherheit] - source: https://docs.aedifion.io/en/products/general/security/overview/ status: 200 keywords: [TLS, X.509, RBAC, penetration tests, ISO 27001, Hetzner] - source: https://cdn.prod.website-files.com/6942a43e5bcce46ebe9f73a1/696e525b02ad6e609db2751c_2025_aedifion_certificate_iso-iec-27001_de.pdf status: 200 gaps: - No SOC 2 report. - No trust portal or subprocessor list. - No published vulnerability disclosure policy, security.txt or bug bounty - see below. vulnerability_disclosure: published: false security_txt: false bug_bounty: false policy_url: null note: >- Probed /.well-known/security.txt on all six known hosts (all 404 or SPA shell), and checked /security, /responsible-disclosure and /vulnerability-disclosure. No responsible-disclosure policy, no security@ address and no bug-bounty program was found. The only route for a researcher is the general contact address. For an ISO 27001 certified operator of building control systems, a published disclosure channel is the clearest gap in this profile.